Fisheries and Oceans Pêches et Océans 
Canada Canada 


Material Privacy Breach Determination 


À material privacy breach has the highest risk impact and is defined as: 


+ involving sensitive personal information (1); and 
+ Could reasonably be expected to cause serious injury or harm to the individual (2) and/or involves a large 
number of affected individuals (3). 


1. Sensitive Personal Information Criteria 


1a) “Sensitive personal information” includes, but is not limited to, the following: 


Yes [1 No Information compiled and identifiable as part of an investigation into a possible violation of 
law; 


Yes © No & information on the eligibility for social benefits or the determination of benefit levels; 


Yes (] No information containing personal recommendations or evaluations, personal opinions about a 
sensitive subject, character references, or personnel evaluations; 


SPP OPIS EAA ET PTS RDS TOOL ELECTR 


including birthdate and Social Insurance Number. 


Certain tombstone information, 


Yes Li No 


1b) Specific elements of sensitive information: Biographical information, contact information, criminal checks, 
educational information, credit card information, date of birth, citizenship status, credit history, employee personnel 
information, financial information, driver's licence number, place of birth, signature, gender, name, photographs of 


individual 


2. Serious Injury or Harm Criteria and/or 


2a) “Serious injury to the individual” includes the following: 


ATIP FILE NUMBER: PB-2018-00394 


000001 


Fisheries and Oceans Pêches et Océans 
Canada Canada 


000002 


Brief description of potential injury: There is a potential for identity theft causing financial loss due to this breach. 


. Involves a Large Number of Affected Individuals 


3a} The institution must also take the number of affected individuals into consideration when determining a material 
privacy breach, as the more individuals affected raises the risk of causing serious injury or harm. 


Number of individuals affected: 1 


Material Privacy Breach Determination Summar 


& No O Sensitive Personal Information Criteria Met. 


and/or 
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From: Polkes rah 


To: Bolger, Charlotte 

Subject: FW: Privacy Breach Report 

Date: A) Wy 11, a 1:52:30 PM 
Attachments: i p N : 


BAD He ASS SAIN GERS GS aD ADEA RR DDR ADAH AVS ARIA A Ca Aa VED EC aa a Ya Waa oe iad eee GG RGO SR 


Hi Charlotte, 


Please find attached the electronic copy of the preliminary report so you can use it to TH out the 
ATIP version. 


| spoke to Darren and he explained a bit more about the incident, you could use this information in 
the investigation portion of the repart. He said that when they send a file to another department 
there is a transmittal note which confirms that tt was sent. In this case, as the file was sent more 
than two years ago, the transmittal note would already have been destroyed so we dont have 
anything further to confirm that it was sent, just a note on the file. When he followed up with 


Transport they said they hadn’t received the file, and that they don’t have it. He sent an emali to the 
manager at Transport asking them to double check that they did not have the records, but g's been 


waiting a week and has not heard back from them. 


He asked if we would be contacting the Transport ATIP shop about the breach and mentioned that 
he did that in the past at another department where he worked. He was saying that as we can’t 


confirm where the documents may have been misplaced it could be either of our departments. | will 


also mention the possibility of contacting their ATIP office to Melanie as I'm interested to see if it's 
something she’s done before. 


if you have any questions please let me know. 


Thanks, Sarah 


From: Costain, Darren 

Sent: July-11-18 1:15 PM 

Ta: Polkey, Sarah 

Subject: Privacy Breach Report 


As requested. 


Darren Costain 


Deputy Director, Security Operations 
Fisheries and et Canada / Government of Canada 
noo.cc.ca / Tel: 613 990-1575 / fax: 613 991-3302 


Directeur adjoint, Opérations de sécurité 
Péches et Se u / Gouvernement du Canada 
Ddifo-mon.gc.ca / Tél. : 613 990-1575 / Télécopieur : 613 991-3302 
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Fisheries and Oceans 


Pêches et Océans 
Canada 


Canada 


SUSPECTED PRIVACY BREACH REPORT 


PROTECTED B (WHEN COMPLETED) 


lent Details. 
Date of incident; Time of incident: Location of incident: 


Between November 2, 2016 and June Unknown (DFO or Transport Canada) 
20, 2018 o 
Brief description of the incident (what happened, how it happened, how it was discovered, etc.): 

Personnel Security Screening file for went missing when transferred between departments around 


November 2, 2016. It was only recently discovered missing when we received a request to verify his clearance for another 
department. 


| 
was seconded to DFO | | | | | _.DFO requested | | | file on 
October 6, 2016; however, subsequently cancelled the request because at the time was only on secondment 
with our department. Transport had already transferred the file and DFO received the file on (or around) November 2, 2016. 
DFO immediately returned the file to Transport with explanation that the employee was only on secondment. 


DFO has conducted a throughout search of its files to no avail. 


identify the individual(s) whose personal information was compromised (include contact info if possible). Attach a 
list if necessary. 


H 
H 
H 
r 
i 
: 


His home address on file is : 


Is the individual(s) aware of the incident? Format of information involved: 
ov Yes [JNo 
What elements of personal information were involved (check all that apply)? 


& Biographical information | [I Biometric information X Citizenship status 
Z Credit card information 
| & Criminal checks/history g & Date of birth 
| X Educational information L Employee identification number (PRI etc.) 
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NET TP RENEE ENT SP RRR IE SERRE ESS x : x Fe 
| Describe the immediate containment measures and/or interventions taken, if any Sina to DFO’s immediate 


& Financial information X Gender 
C Medical information D Name fetes 
X Other ID numbers (FIN, driver's licence etc.) X Photographs of individuals _ 


& Employee personnel information —__ 
Li Language/language preference 


| Opinions or views of, or about, individuals 
L Physical attributes X Place of birth g . Place of death 


EL} Positional information (latitude/longitude etc.) | Z Signature en C Social Insurance Number 
i] Vessel information [} Other (List any other categories of personal information that does not fit anywhere else. Please 
Specify below. 


Other elements (i.e. information that may cause harm to an individual, if breached): 


Containment Measures and TBS’ Office of Primary 
The employee was advised immediately and a new credit check was completed and provided to the employee to ensure no 
identity theft occurred. A throughout search of DFO files was completed without success. Transport Canada, Personne! 

security Division was advised and requested to verify files, no response to date. 
Has the supervisor or program manager been notified of the incident? 


Yes [] No 


H 


List all of the individuals involved and their role in the incident (witness, investigator, individual who may have 
caused the breach, victims, etc.) Attach a list if necessary. 


L 


1. Name Title/Position Contact Information 


Darren Costain Deputy Director, Security Operations Darren. .Costain@dfo-mpo.gc.ca 


Describe how this person was involved? 


Informed affected employee, directed a serach of files and contacted Transport Canada. _ 
2. Name Title/Position 


Contact Information 


Julie Beaubien Manager Personnel Security and Julie. Beaubien@dfo-mpo.gc.ca 
Passports 


Describe how this person was involved? 


Manages personnel security screening section, lead search of files and also contacted Transport Canada 
3. Name | Title/Position Contact Information 


| 3 « 
| Head of Personnel Security — 


July 11, 2018 


Guy Morgan | Transport Canada Guy.Morgan@tc.gc.ca 
Describe how this person was involved? 


Was informed of the incident and requested to verify personnel security files at Transport Canada for missing file. 


Please use the following space to provide any other information that may be relevant to the incident (ie. previous | 
incidents that are similar or related privacy breaches). | 


PART 2- - Assurances © Ä | | _ a : 
i attest that, to m knowlede ge, the Information p Peanted] in the form above i is ; accurate. 
Name/Title/Phone Number: 


Darren Costain — Deputy Director, Security Operations (613) 990-1575 _ 
Date submitted to ATIP: | 
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Bolger, Charlotte | 


From: Afram, Prince 

Sent: Monday, July 16, 2018 3:05 PM 
To: Bolger, Charlotte 

Subject: Privacy breach 

Attachments: Privacy breach_ Charlotte docx 


As discussed. 
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gi en Fisheries and Ocuans Péchase et Ocsans 
Canada Canada 


PRIVACY BREACH REPORT .. nn 
FORATIPUSEONLY =: nn E a 


ATIP FILE NUMBER PB-2018-00161 
PROTECTEDB 


PART 1 — incident Details 
Date of incident: 

Between November 2, 2016 and 
June 20, 2018 

Brief description of the incident as reported to ATIP (what happened, how it happened, how it was 
discovered, etc. }: 

Personnel Security Screening file for went missing when transferred between 
departments around November 2, 2016. It was only recently discovered missing when we received a 
request to verify his clearance for another department. 


| Time ofincident | Location of Incident ti 
NCR 


was seconded to DFO DFO 
requested file on October 6, 2016; however, subsequently Cancelled the request 
because at the time was only on secondment with our department. Transport had 
already transferred the file and DFO received the file on (or around) November 2, 2016. DFO 
immediately returned the file to Transport with explanation that the employee was only on 
secondment. 


DFO has conducted a thorough search of its files to no avail. 


identify the individual(s) whose personal information was compromised (include contact info if 
possible). Attach a list if necessary. en 


z Yes LINO CiElectronic Paper Other (describe): 


i 
Elements of personal information breached (Please refer to Categories of Personal Information) 
-Biographical information 
-Contact information 
-Criminal checks/history 
-Educational information 
-Credit card information 
-Date of birth 
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-Gitzenship status 

-Credit history 

-Employee personnel information 

-Financial information 

-Other ID numbers (FIN, driver's license etc) 
-Place of birth 

-Signature 

-Gender 

-Name 

-Photographs of individuals 

Immediate containment measures taken: 
The employee was advised immediately and a new credit check was completed and provided to the 
employee to ensure no identity theft occurred. A throughout search of DFO files was completed 
without success. Transport Canada, Personnel Security Division was advised and requested to 


Has the supervisor or program manager been notified of the incident? Yes L No 


1. Name | Title/Position Contact Information | 
Darren Costain | Deputy Director, Security Operations | Darren.Costain@dfo-mpo.gc.ca 
Describe how this person was involved? | 
informed affected employee directed a search of files and contacted Transport Canada.  — — —< | 
2. Name | Title/Position Contact Information | 
Julie Beaubien | Manager Personnel Security and Julie Beaubien@dfo-mpo.gc.ca | 

Pe sac TEE i ON ee nie | 

| Describe how this person was involved? 


| Manages personnel security screening section, lead search of files and also contacted Transport | 
| Canada E Seca) 
: 3. Name | Title/Position Contact Information | 
| Guy Morgan | Head of Personnel Security-Transport Guy Morgan@tc.gc.ca | 
| { 


| Describe how this person was involved? 
| Was informed of the incident and requested to verify personnel security files at Transport Canada 


| for missing file. 
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PART 2 - Analysis 


Improper or unauthorized collection of personal information 
Improper or unauthorized disclosure of personal information 


improper or unauthorized disposal of personal information 


Sensitive Personal information Criteria 


| Information compiled and identifiable as part of an investigation into a possible 


violation of law Yes ii No% | 


| Information on the eligibility for social benefits or the determination of benefit 


Material loss to the individual Yes :} No gi 


| The breach involves a large number (over 100) of affected individuals Li No | 


: Material Privacy Breach Determination Summary 


| Serious injury or harm criteria met and/or involves a large number of affected 
: individuals 


Yes No 7 | 
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PART 3- Risk Impact to the Individual 


Is there a possibility of risk impact to the individual regarding the following: 


Financial loss to the individual(s) through identity theft or fraud, inconvenience due to changing 
financial arrangements, loss of wages or of job lost employment or business opportunities, loss of 
promotion, increased costs or loss of insurance, pension loss, or any other financial implication. 


Yes X No ii 


Health implications — physical safety (security risk) or mental harm to the individual(s) through 
violence, loss of sleep, heart attack, stress or a breakdown of relationships, physiological impact 
{loss of sleep, stomach problems, heart attack, long-term medication regime), psychological impact 
(stress, breakdown of relationships}. 


Yes!) NoN 


| loss of professional/personal standing. 


| Yes O No i 


i 
; 
H 


Legal harm to the individual(s) through civil or criminal charges, fines, or imprisonment, possible 
| application of foreign laws (disclosure to foreign government for unrelated use). 


Risk Impact to DFO/CCG - Severity of Impact 


| Negligible 
Loss of Confidence or Trust i 
_Legal Proceedings (Lawsuit) = ee es, 
K = 
(Operational Ham  _ | RW | © 
Financial BO 


Operational Harm 


Financial cae a ee ee 


1 to the individual(s) through hurt, humiliation, embarrassment, discrimination, or | _ o 
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5. Summary of investigations and Findings 


spoke to Darren from DFO security July 11, 2018. DFO believes they sent 
Personnel Security Screening file back to Transport Canada in 2016. However, DFO recently 
pall doe to find the file and it appeared that neither DFO nor Transport Canada had it. The 
mittal slip tha irmed DFO sending the file to Transport Canada has been destroyed. 
There! ore, it is unclear whether the file was lost by DFO or by Transport Canada. 


The loss of this file causes a risk of identify theft or fraud to 
material because it has the potential to cause serious injury or harm. 


. This breach is therefore 


This is a material privacy breach, but it not known at this time whether this is a DFO privacy breach 
or à Transport Canada privacy breach. 


Part6—Recommendations _ 


| Training 
: The employee who caused this privacy breach should update their privacy awareness training. 
| Management should also encourage employees within their business unit to update their security 
| and privacy awareness training. 


| As per standard procedure, the following will receive a copy of this report: staff member who 

_ caused the breach (and/or was involved in the breach); staff member's manager: ATIP Director & 
: Deputy Director (Policy and Privacy Division); Departmental Security Officer (DSO); and Chief 

| Privacy Officer (CPO). 


| Notification 


: The individual involved has already been notified. 


Part7 — Signatures 


| Employee Signature 


ATIP Investigator Charlotte Bolger 


Deputy Director, ATIP | Melanie Davis 


A/Director, ATIP Jonathan Macdonald 
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Bolger, Charlotte | | 


From: Afram, Prince 

Sent: Tuesday, July 17, 2018 1:57 PM 
To: Bolger, Charlotte 

Subject: RE: Privacy Breach security file 


So in that case we can leave the criminal history uncheck under sensitive personal information 


Sent: July-17-18 1:49 PM 
To: Afram, Prince 
Subject: Privacy Breach security file 


Hi Prince, 


| emailed Darren Costain with some questions about the security file that was lost. Darren said that the file included the 
fact that the individual did not have criminal history. Would this still count as personal information? 


Thanks, 


Charlotte 
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Bolger, Charlotte 


From: Bolger, Charlotte 

Sent: Tuesday, July 17, 2018 2:00 PM 
To: Davis, Melanie 

Subject: Draft Privacy Breach Report 
Attachments: Draft PB report.docx 

Hi Melanie, 


Here is the updated privacy breach report. 
Thanks, 


Charlotte 


000015 


s.19(1) 


Fisheries and Oceans Pêches et Océans 
Canada Canada 


PRIVACY BREACH REPORT 
FOR ATIP USE ONLY 


ATIP FILE NUMBER PB-2018-00161 
PROTECTED B 


n ta 
| Date of Incident: Time of Inciden Location of Incident: 
| Between November 2, 2016 and NCR 


| June 20, 2018 
Brief description of the incident as reported to ATIP (what happened, how it happened, how it was 
discovered, etc.): 


Personnel Security Screening file for went missing when transferred between 
departments around November 2, 2016. It was only recently discovered missing when we received a 
request to verify his clearance from another department. 


was seconded to DFO . DFO 
requested file on October 6, 2016; however, subsequently cancelled the request 
because atthe time was only on secondment with our department. Transport had 
already transferred the file and DFO received the file on (or around) November 2, 2016. DFO 
immediately returned the file to Transport with explanation that the employee was only on 
secondment. | 


DFO has conducted a thorough search of its files to no avail. 


identify the individual(s) whose personal information was compromised (include contact info if = 
possible). Attach a list if necessary. 


Is the individual(s) aware of the incident? | Format of information involved: 
Kk Yes LINO [Electronic XPaper ClOther (describe): 
) 


Categories of Personal Information 


Elements of personal information breached (Please refer to 
-Biographical information 
-Contact information 
-Criminal checks/history 
-Educational information 
| -Credit card information 
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-Date of birth 
-Citizenship status 
-Credit history 
-Employee personnel information 
-Financial information 
-Driver’s licence number 
-Place of birth 
-Signature 
-Gender 
; -Name 
| -Photographs of individuals 
immediate containment measures taken: 
| The employee was advised immediately and a new credit check was completed and provided to the 
| “employee to ensure no identity theft occurred. A thorough search of DFO files was completed 
| without success. Transport Canada, Personnel Security Division was advised and requested to 
| verify files, no response to date, 


| Has the supervisor or program manager been notified of the incident? Yes L No 


| 1. Name Title/Position Contact Information 
| Darren Costain | Deputy Director, Security Operations | Darren.Costain Mdfo-mpo.gc.ca 
| Describe how this person was involved? 

| Informed affected employee directed a search of files and contacted Transport Canada. 


"2. Nat 2. Name Title/Position Contact Information 
Julie Beaubien | Manager Personnel Security and | Julie. Beaubien@dfo-mpo.gc.ca 
_| Passports | 


Describe how this person was involved? 
Manages personnel security screening section, lead search of files and also contacted Transport 
Canada 
3. Name | Title/Position | Contact Information 
| Head of Personnel Security-Transport | Guy Morgan@tc.gc.ca 
| Canada | 
Describe how this person was involved? 
Was informed of the incident and requested to verify personnel security files at Transport Canada 


: for missing file. a 


Guy Morgan 
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| PART 2- Analysis Ru | Bugs = or 5 m 


Improper or unauthorized collection of personal information Yes I No & | 


Improper or unauthorized disposal of personal information 


| Sensitive Personal Information Criteria 


| Information compiled and identifiable as part of an investigation into a possible 
| violation of law 


| information on the eligibility for social benefits or the determination of benefit 
levels 


| Information containing personal recommendations or evaluations, personal 
| opinions about a sensitive subject, character references, or personnel Yes | No Z 
; evaluations | 


| Certain tombstone information, including birthdate and Social Insurance Number Yes 


| Serious Injury or Harm Criteria and/or Involves a Large Number of Affected Individuals 


Material loss to the individual Yes ( No & 


| The breach involves a large number (over 100) of affected individuals Yes L No x 


A A AAA AAA A AAA a RAR AR ARR nement een den naana manne ne ns nene sans one ns 


Material Privacy Breach Determination Summary 


| Serious injury or harm criteria met and/or involves a large number of affected 


DrD Yes K No 
| individuals 
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PART 3- Risk Impact to the Individual 


Is there a possibility of risk impact to the individual regarding the following: 


Financial loss to the individual(s) through identity theft or fraud, inconvenience due to changing 
financial arrangements, loss of wages or of job lost employment or business opportunities, loss of 
promotion, increased costs or loss of insurance, pension loss, or any other financial implication. 


Yes K No 

Health implications ~ physical safety (security risk) or mental harm to the individual(s) through 
violence, loss of sleep, heart attack, stress or a breakdown of relationships, physiological impact 
(loss of sleep, stomach problems, heart attack, long-term medication regime), psychological impact 
(stress, breakdown of relationships). 


Yes No 


Reputational harm to the individual(s) through hurt, humiliation, embarrassment, discrimination, or 
loss of professional/personal standing. 


Yes O No 


Legal harm to the individual(s) through civil or criminal charges, fines, or imprisonment, possible 
application of foreign laws (disclosure to foreign government for unrelated use). 


Yes O No 


Risk Impact to DFO/CCG - Severity of Impact- 


Negligible | Low 


Loss of Confidence or Trust 


So 


uidelin ine on n Definin „Authentic canon Regui Nemen: 


Risk Aaaa to DFO/CCG - Probability of Occurrence 


Unlikeh Re ta T Ver ke 
Loss of osae dence or 
Trust 


Lawsuit 

a tat 55 — = 
‘OperationalHam | | © | © | © | 0 
E SNS D DA EN IE NE EE D = ER = 
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PART 5 — Summary of investigations and Findings : | | 
The Deputy Director of Security Operations, DFO and the Manager of Personnel Security TE 


Passports, DFO believe 


security file was sent to Transport Canada, but have no 


way to confirm this, as they believe the transmittal slip was destroyed. Transport Canada has not | 
been able to locate the file; therefore, it can be presumed to be lost. The security file contains a | 
large amount of sensitive information, which makes identity theft or fraud a real possibility if it is not | 
recovered. The breach is therefore material because it has the potential to cause serious injury or | 
| harm to 


Training 
The employee who was responsible for this privacy breach should update their privacy awareness 
training. Management should also encourage employees within their business unit to update their 
| security and privacy awareness training. 


| As per standard procedure, the following will receive a copy of this report: staff member who 
_ caused the breach (and/or was involved in the breach); staff member’s manager; ATIP Director & 
| Deputy Director (Policy and Privacy Division); Departmental Security Officer (DSO); and Chief 
Privacy Officer (CPO), 


| Program recommendation 
| Personnel Security and Passports should develop a method to better keep track of security files the 


| program is sending and receiving. Transmittal slips may need to be kept for a longer time. 
| Otherwise, a record should be kept of which transmittal slips are being destroyed. 


Notification 


| The individual involved has already been notified. 


| 


H 
a EEEEEREERELEVEREREDEUGERBEREEE 


| | Employee — Signature Date 


| ATIP Investigator | Charlotte Bolger | 
| Deputy Director, ATIP | Melanie Davis 


A/Director, ATIP Jonathan Macdonald | 
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Bolger, Charlotte | 


From: Bolger, Charlotte 

Sent: Wednesday, July 18, 2018 9:00 AM 
To: Davis, Melanie 

Subject: Abridged privacy breach report 
Attachments: PRIVACY BREACH REPORT.pdf 
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PRIVACY BREACH REPORT 
FOR ATIP USE ONLY 


ATIP FILE NUMBER PB-2018-00161 
PROTECTED B 


Date of incident: i j ; Location 
Between November 2, 2016 and NCR 
June 20, 2018 | 
Brief description of the incident as reported to ATIP (what happened, how it happened, how it was 
discovered, etc.): 


Personnel Security Screening file for | _ went missing when transferred between 
departments around November 2, 2016. It was only recently discovered missing when we received a | 
request to verify his clearance from another department. 


was seconded to DFO . DFO 
requested file on October 6, 2016; however, subsequently cancelled the request 
| because at the time was only on secondment with our department. Transport had 

| already transferred the file and DFO received the file on (or around) November 2, 2016. DFO 

| immediately returned the file to Transport with explanation that the employee was only on 

| secondment. 


| DFO has conducted a thorough search of its files to no avail. 


Identify the individual(s) whose personal information was compromised (include contact info if 
possible). Attach a list if necessary. 


Is the individual(s) aware of the incident? | Format of information involved: 
(lElectronic Paper (Other (describe): 


al informatio 
-Biographical information 
-Contact information 
-Criminal checks 
-Educational information 
-Credit card information 
-Date of birth 
-Citizenship status 
-Credit history 
-Employee personnel information 
-Financial information 
-Driver's licence number 
| -Place of birth 
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| -Signature 
-Gender 
| -Name 
| -Photographs of individuals 
immediate containment measures taken: 
| The employee was advised immediately and a new credit check was completed and provided to the 
| employee to ensure no identity theft occurred. A thorough search of DFO files was completed 
| without success. Transport Canada, Personnel Security Division was advised and requested to 
| verify files, no response to date. 


| Has the supervisor or program manager been notified of the incident? Yes Li No 


1. Name Title/Position Contact Information 
Darren Costain Deputy Director, Security Operations | Darren.Costain@dfo-m| 


Describe how this person was involved”? 
| Informed affected employee directed a search of files and contacted Transport Canada. 


| 2. Name Title/Position Contact information 
| Julie Beaubien Manager Personnel Security and Julie. Beaubien@dfo-mpo.gc.ca 
| Passports 


| Describe how this person was involved? 
Manages personnel security screening section, lead search of files and also contacted Transport 
Canada 


3. Name | Title/Position | Contact Information 
| Guy Morgan Head of Personnel Security-Transport | Guy Morgan@tc.gc.ca 
| Canada 


Describe how this person was involved? 
Was informed of the incident and requested to verify personnel security files at Transport Canada 
for missing file. 
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Bolger, Charlotte | 


From: Davis, Melanie 

Sent: Wednesday, July 18, 2018 9:15 AM 
To: "Anne .Blais@tc.gc.ca' 

Ce: Bolger, Charlotte 

Subject: RE: Privacy Breach 

Attachments: PRIVACY BREACH REPORT.pdf 

Hi Anne, 


You will find attached, background information on the privacy breach we discussed this morning. If you could follow-up 
with Personnel Security at Transport Canada to verify if Transport Canada has a record of receiving the file and/or if the 
file was ever found by Transport Canada it would be greatly appreciated. 


Thanks, 


Melanie Davis 


Deputy Director, ATIP Secretariat 
Fisheries and Oceans Canada / Government of Canada 
melanie. davis@dfo-mpo.gc.ca / Tel: 613-990-3499 or (BlackBerry) 


Directrice adjointe, Secrétariat de VAIPRP 
Pêches et Océans Canada / Gouvernement du Canada 
melanie davis@dfo-mpo.gc.ca / Tél: 613-990-3499 ou | (BlackBerry) 


if you have received this communication by mistake, please notify the sender immediately and delete the communication without printing, copying or 
forwarding i. Thank you. / Si vous avez regu cette communication par erreur, veulllez en aviser expéditeur immédiatement et la supprimer sans 
Firiprimer, le copier, ou ia faire suivre. Merci. 
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PRIVACY BREACH REPORT 
| FOR ATIP USE ONLY 


ATIP FILE NUMBER PB-2018-00161 
PROTECTED B 


Date of medeni Time of Incident: Location of Incident: 

Between November 2, 2016 and NCR 

June 20,2018 | E | 

Brief description of the incident as reported to ATIP (what happened, how it happened, how it was 
discovered, etc.): 


Personnel Security Screening file for went missing when transferred between 
departments around November 2, 2016. It was only recently discovered missing when we received a 
request to verify his clearance from another department. 


was seconded to DFO . DFO 
requested | file on October 6, 2016; however, subsequently cancelled the request 
because at the time was only on secondment with our department. Transport had 
already transferred the file and DFO received the file on (or around) November 2, 2016. DFO 
immediately returned the file to Transport with explanation that the employee was only on 
secondment. 


DFO has conducted a thorough search of its files to no avail. 


Identify the individual(s) whose personal information was compromised (include contact info if 
possible), Attach a list if necessary. 


Is the individual(s) aware of the incident? | Format of information involved: 
Electronic XPaper Other (describe): 


Elements of personal information breached (Please refer to Categories of Personal Information) 
-Biographical information 
-Contact information 

-Criminal checks 

-Educational information 

-Credit card information 

-Date of birth 

-Citizenship status 

-Credit history 

-Employee personnel information 
-Financial information 

-Driver's licence number 

-Place of birth 
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-Signature 
-Gender 
-Name 
-Photographs of individuals 

immediate containment measures taken: | 
The employee was advised immediately and a new credit check was completed and provided to the | 
employee to ensure no identity theft occurred. A thorough search of DFO files was completed | 
without success. Transport Canada, Personnel Security Division was advised and requested to 


verify files, no response to date. | 
Yes L No 


Has the supervisor or program manager been notified of the incident? 


Contact Information 
Darren.Costain@dfo-mpo. 


| 1. Name Title/Position 
| Darren Costain Deputy Director, Security Operations 


Describe how this person was involved? 
| informed affected employee directed a search of files and contacted Transport Canada. 
2. Name Title/Position Contact Information 
| Julie Beaubien Manager Personnel Security and Julie. Beaubien@dfo-mpo.gc.ca 
See ee Passports 
| Describe how this person was involved? 
| Manages personnel security screening section, lead search of files and also contacted Transport 
| Canada 


3. Name E Title/Position Contact Information 
Guy Morgan Head of Personnel Security-Transport | Guy Morgan@tc.gc.ca 
Canada 


Describe how this person was involved”? 
Was informed of the incident and requested to verify personnel security files at Transport Canada 
for missing file. 
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From: Costain, Darren 


To: . Bolger r 

Ce: Davis, Melanie 

Subject: RE: Suspected privacy breach-lost personnel file 
Date: Wednesday, July 18, 2018 9:47:05 AM 


NEE OS TREE LETTERS ERSTELLTEN OS EE EE CC SP PSS CS SES RE ESS SSO OO CaO S SEILER 


Hi Charlotte, 
No, the SIN number should not have been on the file. 


Yes for ethnic origin, since the file has place of birth. For associations it does contain 
employment history, contact information for family members and three references. 
(not racial, religious, political or lifestyle). 


Darren 


Sent: July-18-18 9:06 AM 

To: Costain, Darren 

Cc: Davis, Melanie 

Subject: RE: Suspected privacy breach-lost personnel file 


Thanks Darren, 

Sorry | have two more quick questions: 

Did the missing fille contain the employee's SIN number? 

Did the missing file contain information concerning the employee's racial, ethnic origin, religious, 
political beliefs and associations or lifestyle? 

Thanks, 


Charlotte 


From: Costain, Darren 

Sent: Tuesday, July 17, 2018 12:06 PM 

To: Bolger, Charlotte <Charlotte Bolger@ dfo-mpo.gc.ca> 
Cc: Davis, Melanie <Melanie.Davis@dfo-mpo.gc.ca> 
Subject: RE: Suspected privacy breach-lost personnel file 


Hi Charlotte, 
See response below.... 


Darren 


Sent: July-17-18 12:01 PM 
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To: Costain, Darren 
Cc: Davis, Melanie 
Subject: Suspected privacy breach-lost personnel file 


Good morning, 


| am working on the suspected privacy breach that you reported to us last week. I’m wondering if 
you know whether the security file that was lost contains 


a) The individual’s criminal history (in this case there would have been an indication of no criminal 
history) 


Or 


b) Information containing personal recommendations or evaluations, personal information about 
a sensitive subject, character references or personnel evaluations. (No, no such information) 


Thank you, 


Charlotte Bolger 


ATIP Advisor 
Fisheries and Oceans Canada / Government of Canada 
82.28 /Tel: (613) 991-6631 


Charlotte Bolger®@dfo-mpso 


Conseilliere de / AIPRP 


without printing, copying or forwarding it Thank you. / Si vous avez recu cetie communication par erreur, veulliez en aviser 
l'expéditeur finmédiaiement et ig supprimer sans Ülmprimer, ia copier, ou la faire suivre Merci. 
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Bolger, Charlotte | 


From: Blais, Anne <Anne Blais@tc.gc.ca> 
Sent: Friday, August 24, 2018 11:39 AM 

To: Davis, Melanie 

Ce: Bolger, Charlotte; Senevongsa, Stefany 
Subject: RE: Privacy Breach 


Hi Melanie, 


Pve asked our colleagues in Personnel Security to provide input. 
but will follow up with you when I return. 


Thanks, 


Anne Blais 
Anne Blais@ic.ec.ca 
613-949-4172 


Sent: Wednesday, August 22, 2018 12:28 PM 

To: Blais, Anne <Anne.Blais@tc.gc.ca> 

Cc: Bolger, Charlotte <Charlotte. Bolger@dfo-mpo.gc.ca> 
Subject: RE: Privacy Breach 


Hi Anne — Is it possible to get a status update on the breach? 


Thanks, 


From: Davis, Melanie 

Sent: July-26-18 8:53 AM 
To: ‘Blais, Anne’ 

Ce: Bolger, Charlotte 
Subject: RE: Privacy Breach 


Hi Anne, 
| am just wondering what the status of this breach is. 
Thanks, 


Melanie 


Sent: July-18-18 10:35 AM 
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To: Davis, Melanie 
Subject: RE: Privacy Breach 


Success! Thank you! 


Anne Blais 
Anne Blais@tc.ec.ca 
613-949-4172 


From: Davis, Melanie [ 


mallto:Mel 


Subject: RE: Privacy Breach 


Ok- i just resent. Please let me know if it worked that time. 


000030 


From: | Dayis, Melanie 


To: Bolger, Charlotte 
Subject: FW: Privacy Breach 
Date: Tuesday, August 28, 2018 9:49:26 AM 


Attachments: PRIVACY BREACH ee 


D Ca DNA a Soy EG DO DO CaN SO CSS RD a CESS GO AOU D a ca og Tena Aa SS AAAS SS CON Cae Sag eg LLCS ee aS ONE aa SSeS cea gL aoe ES TSC RO SL SC SEC aie Lag LSS RSS a CeCe Lee a bee oa Sab see TETE EN TT a aac 


From: Choiniére, Angie [mailto: Angie. Choiniere@tc. gc. al 

Sent: August-24-18 3:52 PM 

To: Blais, Anne; McCool, Loretto; Senevongsa, Stefany; Beaubien, Julie; Davis, Melanie; Bolger, Charlotte 
Cc: Morgan, Guy; Cadieux-Bruneau, Josee; Wattie, Katharine; St Amour, Terri 

Subject: Privacy Breach 


Good afternoon, 
The report from DFO is not complete, 


| was initially contacted by Julie Beaubien in regards to this matter. An extensive search was 
conducted here at Transport Canada to no avail. The electronic file indicates the original personnel 
security file was transferred to DFO on 2016-10-26. There is no subsequent record of a returned file 
in our database. 


| communicated with CSIS to inquire which department held the clearance as per their records. On 


July 3 = 2018, C5IS confirmed by email that DFO held the secret clearance. | immediately 
communicated this information to Julie Beaubien by ae 


in this regard, we do not feel that this is a Transport Canada privacy breach. 


Angie Choiniere 

Superintendent, Security Screening Programs / Surintendant des programmes de filtrage de sécurité 
Transport Canada | Transports Canada, Place de Ville, Tower C/Tour © 

Ottawa, ON | Ottawa o a ONS 
Email | courriel : z LÀ RNC OU Ce 
Telephone | Tel aphone : a 990-1624 
Government of Canada | Gouvernement du Canada 


From: Blais, Anne 

Sent: Friday, August 24, 2018 11:38 AM 
To: McCool, Loretto <loretio.mecocifite.s 
Ce: Senevongsa, Stefany <Stel: 
Subject: FW: Privacy Breach 


Hi Guy and Loretto, 


You are a ee aware e of this a, It seems as though someone's 


sie 
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some light on the matter? 


DFO ATIP is managing the privacy incident and would like to know what, if 
anything, has been done from TÜ’s side. 


Please note that | will be out of the office | 
Thanks, 


Anne pie 


Gas 949- 4172 


From: pauls Wenne planie is@ dfo- 
Sent: Wednesday, July 18, 2018 10. 28 / AM 


To: Blais, Anne «Anne Blais@tc.gcca> 
Subject: FW: Privacy Breach 


From: Davis, Melanie 
Sent: July-18-18 9:15 AM 
To: ‘Anne. Blais@tc.gc.ca’ 
Cc: Bolger, Charlotte 
Subject: RE: Privacy Breach 


Hi Anne, 


You will find attached, background information on the privacy breach we discussed this morning. If 
you could follow-up with Personnel Security at Transport Canada to verify if Transport Canada has a 

record of receiving the file and/or If the file was ever found by Transport Canada it would be greatly 
appreciated, 


Thanks, 


Melanie Davis 


aide Director, ATIF Secretariat 
o and Oceans = ana Bu / Government of Canada 
melanie cavis@dto-smpa.se.ca / Tel: 613-990-3499 or (BlackBerry) 


Directrice adjointe, Secrétariat de VAIPRP 
Päches et Oceans Canada / Gouvernement du Canada 


ial ipo.ge.ca / Tél: 613-990-3499 au (BlackBerry) 
if you have received this communication by mistake, please naury ine sender immediately and delete the communication 
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without printing, copying or forwarding IE Thank you. / Si vous avez recu cetie communication par erreur, veuilles en aviser 


l'expéditeur immédiatement et is supprimer sans fimorimer, la copier, ou la faire suivre, Merci. 
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PRIVACY BREACH REPORT 
FOR ATIP USE ONLY 


ATIP FILE NUMBER PB-2018-00161 
PROTECTED B 


Between November 2, 2016 and 

June 20,2018 _ 

Brief description of the incident as reported to ATIP (what happened, how it happened, how it was 
discovered, etc.): 


Personnel Security Screening file for went missing when transferred between 
departments around November 2, 2016. It was only recently discovered missing when we received a 
request to verify his clearance from another department. 


was seconded to DFO . DFO 
requested | file on October 6, 2016; however, subsequently cancelled the request 
because at the time was only on secondment with our department. Transport had 
already transferred the file and DFO received the file on (or around) November 2, 2016. DFO 
immediately returned the file to Transport with explanation that the employee was only on 
secondment. 


DFO has conducted a thorough search of its files to no avail. 


Identify the individual(s) whose personal information was compromised (include contact info if 
possible). Attach a list if necessary. 


Is the individual(s) aware of the incident? Format of information involved: 


Yes CINo LIElectronic Paper LJOther (describe): 


Elements of personal information breached (Please refer to gategori es of Personal Information) 
-Biographical information 
-Contact information 

-Criminal checks 

-Educational information 

-Credit card information 

-Date of birth 

-Citizenship status 

-Credit history 

| -Employee personnel information 
| -Financial information 

| -Driver's licence number 

| -Place of birth 
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-Signature 

-Gender 

-Name 

-Photographs of individuals 

Immediate containment measures taken: 


The employee was advised immediately and a new credit check was completed and provided to the | 


employee to ensure no identity theft occurred. A thorough search of DFO files was completed 
Without success, Transport Canada, Personnel Security Division was advised and requested to 
verify files, no response to date. 


Has the supervisor or program manager been notified of the incident? 


| z Yes L No 


4. Name Title/Position Contact Information 
Darren Costain Deputy Director, Security Operations | Darren.Costain@ 
Describe how this person was involved? 

informed affected employee directed a search of files and contacted Transport Canada. —ć  ć 
2. Name | Title/Position Contact Information 

Julie Beaubien | Manager Personnel Security and | Julie. Beaubien@dfo-mpo.gc.ca 
ee | Passports | 

| Describe how this person was involved? 

Manages personnel security screening section, lead search of files and also contacted Transport 
Canada 


3. Name  Title/Position | Contact Information 
| Guy Morgan Head of Personnel Security-Transport | Guy Morgan@tc.gc.ca 
| Canada | en 


| Describe how this person was involved? 
| Was informed of the incident and requested to verify personnel security files at Transport Canada 
| for missing file. 
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Bolger, Charlotte 


From: Bolger, Charlotte 

Sent: Wednesday, September 5, 2018 10:41 AM 
To: Davis, Melanie 

Subject: Draft OPC report 

Attachments: Draft OPC report September 5.docx 

Hi Melanie, 


I've completed the draft OPC report for your review. 
Thanks, 


Charlotte 
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Office of the Commissariat 
O Privacy Commissioner à la protection de 
of Canada la vie privée du Ganada 


Privacy Act Breach Report 


For Use by Government of Canada Institutions 


Reporting Breaches Under the Privacy Act 


Federal institutions subject to the Privacy Act are required to notify the Office of the Privacy 
Commissioner of Canada (OPC) and the Treasury Board of Canada Secretariat of all material 
privacy breaches and of the mitigation measures being implemented, if the breach involves sensitive 
personal information and could reasonably be expected to cause serious injury to the individual. 


This reporting form outlines the information that should be provided to the OPC. Report the breach 
promptly rather than waiting to compile all the information requested in the form. Please note that the 
completed report is intended to provide detailed information about the breach itself but must not 
include personal information or protected/classified information. | 


The breach report will help determine the type of intervention required by the OPC, such as an 
informal discussion or an investigation. 


Federal institutions should also refer to the Treasury Board's Guidelines for Privacy Breaches. They 
may also wish to refer to our office’s private sector guide, Key Steps for Organizations in Respondin 


lo Privacy Breaches. 


Date of Breach and Contact Information: 


| Between November 2, 2016 and June 20, 2018 


Fisheries and Oceans 


Jonathan Macdonald A/Director Access to Information and Privacy 
200 Kent Street, 4° Floor, Ottawa, Ontario K1A 0E6 
613-996-8937 

jonathan.macdonald@dfo-mpo.gc.ca 

Darren Costain Deputy Director Security Operations 
200 Kent Street, 4” floor, Ottawa, Ontario K1A 0E6 
613-990-1575 

darren.costain@dfo-mpo.gc.ca 
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Privacy Act Breach Report 


Melanie Davis A/Deputy Director, Privacy and Policy Divison 
200 Kent Street, 4" floor, Ottawa, Ontario K1A 0E6 
613-990-3499 

Melanie. Davis@dfo-mpo.gc.ca 
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Privacy Act Breach Report 


Details of the Breach: 


DFO requested a paper copy of the affected individual's Personnel Security o] 
Screening file, in error, from Transport Canada on October 6, 2016; however, this 
individual was only on secondment, so DFO should not have requested this file. 
This individual was seconded to DFO from Transport Canada 
. DFO realised their mistake and subsequently ea 
the request for the file. Transport Canada had already transferred the file (their 
records indicate they sent it out October 26, 2016) and DFO received the file on {or 
around) November 2, 2016. According to DFO, the file was immediately returned to 
Transport Canada with an explanation that the employee was only on secondment. | 
However, DFO Security has no record ofreturning it as they have destroyed all | 
transmittal slips from that period oftime Transport Canada does not believe that the 
individuals file was ever returned to them as they have no record of receiving it after 
October 26, 2016. The file was discovered to be missing on June 20, 2018 when 
the individual accepted a position requested his security file 
from DFO. DFO and Transport Canada both conducted thorough searches of their 
records. Neither department was able to locate it. On July 3, 2018 Transport 
Canada verified with CSIS that DFO held the individual’s security clearance. This 
breach affected one individual who is located in the NCR. 


$ 
} 


Biographical information, contact information, financial information, criminal checks, | 
educational information, date of birth, citizenship status, credit history, employes 
personnel information, credit history, driver's licence number, place of birth, 

signature, gender, name, photographs of individual. 


n/a 


PUUPEURDERREPREDEERUUDEELFPEFPEPFUELLRRUEEREEEUEUEUREURDELDRELLUELRLRELRLREURFRELLUFLERUERLRUESDEDRUELDEPPLDLDLLPFLULPEELEPDELFLELDELEPERSPFPEUEPERFEEUEUEFUEUEEEPEUEUELPEREDEDEEEEUEDEPEELDEOEEUEUEREEUEDEDEEEUUEUEPEREUEDEBEEE 


1 


Employee 


n/a-only 1 individual affected 


Paper 
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‘No information has been removed or severed from this page 


Privacy Act Breach Report 
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Privacy Act Breach Report 


Actions Anticipated or Taken Following the Breach: 


| A thorough search was conducted for the missing file but it remains lost. 


| No, the file is still lost 


2 Yes, the affected individual was notified by DFO Security. 


| It has been recommended that the employee responsible for the breach updates 
| their privacy awareness training. It has also been recommended that Peronnel | 
| Security and Passports develop a tracking method of incoming and outgoing 
| files. TBS retention standards should be reviewed and transmittal slips may 

| need to kept for a longer period of time. A record should be kept of which 

| transmittal slips are being destroyed. 


Please submit this form to the Office of the Privacy Commissioner of Canada and the 
Treasury Board of Canada Secretariat through one of the following means: 


By postal mail or by hand: 


Notification Officer Privacy Policy Unit 
Privacy Act Investigations Branch information and Privacy Policy Division 
Office of the Privacy Commissioner of Canada Chief Information Officer Branch 
30 Victoria Street, 1% Floor Treasury Board of Canada Secretariat 
Gatineau, QC K1A 1H3 90 Elgin Street, 4" Floor 

Ottawa, ON KIA OR5 


By email: 


notification@priv.gc.ca sec@ths-sct. oc. Ca 


Should you require additional information, please call the Notification Officer at 819-994-5444 or 
1-800-282-1376 (toll-free). 


Si races 
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From: netar rrer 


To: Davis, Melanie 

Cc: Bolger, Charone; Macé ath. 

Subject: RE: Privacy Breach Report for the OPC and the TBS 
Date: Thursday; oz 6, 2018 3:38:07 PM 
Attachments: l ; | 


D EEE CE 


Looks accurate. 


Darren 


From: Davis, Melanie 

Sent: September-06-18 3:04 PM 

To: Costain, Darren 

Cc: Bolger, Charlotte; Macdonald, Jonathan 

Subject: Privacy Breach Report for the OPC and the TBS 


Hi Darren, 


| reaches, there is a mandatory reporting requirement of 
material privacy breaches to the Off ice of the Privacy Commissioner and the Treasury Board of 
Canada Secretariat. 


PRET EE EN DE ATAPI 


Attached is the material privacy breach report, DFO ATIP proposes sending to the OPC and the TBS. 


Please verily the attached report for accuracy. 
Thanks, 


Melanie 


From: Bolger, Charlotte | 

Sent: September-04-18 11:32 AM 

To: Costain, Darren; Pearcey, Dawn; Davis, Melanie; Macdonald, Jonathan; Boudreau-Brown, Nadine 
Subject: Privacy Breach Final Report - PB-2018-00394 / CB 


This e-mail is being sent on behalf of the A/Director of the ATIP Secretariat, Jonathan 
Macdonald. 


Please note that the attached report is PROTECTED B and can only be saved ona restricted 
network with PKI encryption. 


Good morning, 


Further to the Suspected Privacy Breach Report submitted to the ATIP Secretariat on July 11, 


2018, you will find attached the final report. 


Please note the report contains recommendations for your action. The ATIP Secretariat will 
follow up within 2 weeks to discuss any residual items. 
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If you have any questions or concerns in the meantime, do not hesitate to contact me. 


As per standard procedure, this e-mail is copied to your manager, ATIP Deputy Director (Policy 
and Privacy Division}, ATIP Director, Chief Privacy Officer and the Departmental Security 
Officer. 


Thank you, 


Charlotte Bolger 


ATIP Advisor 
Fisheries and Oceans Canada / Government of Canada 
he poge ta /Tel: (613) 991-6631 


rlotte Boleer@dfo-m 


Conseilliere de l'AIPRP 


without printing, copying or forwarding It Thank you. / Si vous avez reçu celle communication par erreur, venfliez en aviser 


l'expéditeur immédiatement et ia supprimer sans fimprimer, fa copier, au fe faire suivre. Merci, 
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From: Bolger, Charioft 


To: Costain, Darren; Pearcey, Dawn; Davis Melanie; Ma 
Subject: Privacy Breach Final Report - PB-2018-00394 / CB 
Date: Tuesday, September 4, 2018 11:31:00 AM 
Attachments: PB-2013-00394, DH 


RE TGS A ED CE pe a Tate atest BIOL GAD AME Eat EC Ee 


This e-mail is being sent on behalf of the A/Director of the ATIP Secretariat, Jonathan 
Macdonald. 


Please note that the attached report is PROTECTED B and can only be saved on a restricted 
network with PKI encryption. 


Good morning, 


Further to the Suspected Privacy Breach Report submitted to the ATIP Secretariat on July 11, 
2018, you will find attached the final report. 


Please note the report contains recommendations for your action, The ATIP Secretariat will 
follow up within 2 weeks to discuss any residual items. 


If you have any questions or concerns in the meantime, do not hesitate to contact me. 


As per standard procedure, this e-mail is copied to your manager, ATIP Deputy Director (Policy 


and Privacy Division), ATIP Director, Chief Privacy Officer and the Departmental Security 
Officer. 


Thank you, 


Charlotte Bolger 


ATIP Advisor 
Fisheries and Oceans Canada / Government af Canada 
a (Tel: (613) 991-6631 


Conseilliere de F'AIPRP 
Pêches et Océans Canada / Gouvernement du Canada 


“harlotre Be 


iger 


BAERD, 


RR: 


if you have received this communication by mistake, please notify the sender immediately and delete the communication 
witha printing, copying or forwarding if, Thank you. / Si vous aves regu cette communication par erreur, veulllaz en aviser 


l'expéditeur immédiatament ef la supprimer sans imprimer, fa capler, ou la faire suivre, Merci, 


EEE SOS OS SS SO Se RO SR SSSR SR OOD 


000044 


s.19(1) 


PRIVACY BREACH REPORT 
FOR ATIP USE ONLY 
ATIP FILE NUMBER PB-2018-00161 
PROTECTED B 


| Between November 2, 2016 and 
| June 20, 2018 


ee aan REN ER Le 


‘Brief description of th incident as as aoi to ATIP (what a ET howitwas | 
| discovered, etc.): 


| DFO requested Personnel Security Screening file, in error, from Transport 
| Canada on October 6, 2016: however, was only on secondment, so DFO should not 
gave requested this file, was seconded to DFO from Transport Canada 


|DFO realised their mistake and subsequently cancelled the request for the file. 


| | Transport Canada had already transferred | | security file (their records indicate they 
| sent it out October 26, 2015) and DFO received tne tile on (or around) November 2, 2016. 


| According to DFO, the file was immediately returned to Transport Canada with an explanation that 
| the employee was only on secondment. However, DFO Security has no record of returning it as they 
have destroyed all transmittal slips from that period of time. 


| Transport Canada does not believe that 


file was ever returned to them as they have 
‚no record of receiving it after October 26, 2016. 


| 


ss Personnel Security Screening file was discovered to be missing on June 20, 2018 | 
when accepted a position requested his security file from DFO. 


| 


DFO and Transport Canada both conducted thorough searches of their records. Neither department | 
_ was able to locate it. | 


| On July 3, 2018 Transport Canada verified with CSIS that DFO held security 
| clearance. 


RES ON NRC RSR SSSR MS OM ODA SD OISE Mate: 
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identity the individual(s) m personal information w Was “compromised fraude contact info if 
| es e). Attach a list if necessary. 


Is the individual(s) aware of the incident? 


| ‘Biographical informatión 
-Contact information 

-Criminal checks/history _ 
-Educational information 


| -Credit card information 

-Date of birth 

-Citizenship status 

-Credit history 

-Employee personnel information 


F 


-Financial information 
-Driver's licence number 
-Place of birth 

-Signature 

-Gender 

-Name 

-Photographs of individuals 27252 
| immediate containment measures taken: 

| The employee was advised immediately and a new credit check was completed and provided to the 
| employee to ensure no identity theft occurred. A thorough search of DFO files was completed 

| without success. Transport Canada, Personnel Security Division was advised and requested to 

| verify files. Transp sort € Canada was unable to locate these fi iles. 


| Has the supervisor = program manager been notified of the incident? TERE A 


RiYes C No 


| ba en 


1. Name i Title/Position Ea 
| Darren Costain _ | Deputy Director, Security Operations _ 
| Describe how this person was involved? | 
| Informed affected employee directed a search of files and contacted Transport Canada. 
| 2, Name 


| Title/Position | Contact Information Ä 
| Julie Beaubien | Manager Personnel Security and Passports | Julie Beaubien@dfo-mpo.gc.ca | 


Describe how this person was involved? 


| Manages personnel security screening section, led search of files and also contacted Transport | 
| Canada — a eh tae | SR ze a 
| 3, Name | Title/Position | Contact Information 


| Guy Morgan ___ Head of Personnel Security-Transport í Canada | Guy Morgan@tc.gc.ca 
| Describe how this person was involved? 
| Was informed of the incident and requested to verify personnel security files at Transport Canada 


for missing file. __ 


DRE eNO IAAI 


? 
000046 


| Sensitive Personal Information Criteria 


Information compiled and identifiable as part of an investigation into a possible ur rg ne 
oa on of law Yes | No & 


Information on the eligibility for social benefits or the determination of benefit 
levels . | 


| Information containing personal recommendations or evaluations, personal — 
| opinions about a sensitive subject, character references, or personne! 


| Material Privacy Breach Determination Summary 


| Serious injury or harm criteria met and/or involves a mg number of affected ; 
| Yes 
| individuals 
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| L there a possibility of risk impact to the individual regarding the following: 


| | Financial loss to the individual(s) through identity theft or fraud, inconvenience due to changing 
| financial arrangements, loss of wages or of job lost employment or business opportunities, loss of 
| promotion, increased costs or loss of insurance, pension loss, or any other financial implication. 


| Yes & NoD 
There is a possibility of identity theft due to this privacy breach. 


A RE A x 


Health implications — physical safety (security risk) or mental harm to the individual(s) through 

| violence, loss of sleep, heart attack, stress or a breakdown of relationships, physiological Impact 

| (loss of sleep, stomach problems, heart attack, long-term medication regime), psychological impact 
: (stress, breakdown of relationships). 


MAAN REDO RN pe et 


| Yes B NoO 


| This privacy breach may cause the individual stress, | 
| Reputational harm to the individual(s) through hurt, humiliation, embarrassment, discrimination, or | 
| loss of professional/personal standing. 
| Yes I Nog | 
| Legal harm to the individual(s) through civil or criminal charges, fines, or imprisonment, possible | 
| application of foreign laws (disclosure to foreign government for unrelated use). | 


"Financial. 


HR RAR RAR RAR ÉCART RSS ESS SE RER RSR ESS RO AA A RARE AAA à 


| Loss of Confidence or 

‚ Trust 

| Legal Proceedings 
on 


l'operationel Han 
| Financial _ | 
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i i “security file was sent to Transp Canada, but h 
| way. to confi irm this, as s they b cay the transmittal ve was se Transport Canada's records 


: a Canada contacted CSIS and inquired as to which department heid 
| clearance. On July 3, 2018 CSIS confirmed that DFO held secret clearance. 


security file can therefore be presumed to have been lost by DFO. 


| The security file contains a large amount of sensitive information, which makes identity theft or | 
| fraud a real possi ibility if itis not recovered. The breach is therefore material because it has the 
| potential to cause serious injury or harm tol 


| Training 

: The employee who was responsible for this privacy breach should update their privacy awareness 
| training. Management should also encourage employees within their business unit to update their 
ee and privacy awareness training. 


| As per standard procedure, the following will receive a copy of this report: staff member who 

| caused the breach (and/or was involved in the breach); staff members manager; ATIP Director & 
Deputy Director (Policy and Privacy Division); Departmental Security Officer (DSO); and Chief 

| Privacy Officer (CPO). 

P 


rogram recommendation 
Personnel Security should implement a record system for incoming and outgoing files 


Transmitial slips may need to be kept for a longer period of time and a record should be kept of 
which transmittal slips are being destroyed. A review of TBS retention standards may be necessary 


: for DFO Security Operations, as the transmittal slip was destroyed when less than two years had 
| passed. 
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already ed MUTTER 


| As per standard procedure, the following will receive a copy of this report: staff member who M 
reported the breach (and/or was involved in the breach), staff member's manager, ATIP Director | 
/ and Deputy Director, Deparimental Security Officer and Chief Privacy Officer. 


$ 
Ë 
$ 
$ 


crete rasa Ati A A 


LAs a material breach, TBS and the OPC will be notified by the ATIP Secretariat. 


i Employee | Signature | Date 
| ATIP Investigator | Charlotte Bolger PPT A r un u L à, FE 


| Deputy Director, ATIP | Melanie Davis 


| AlDirector, ATIP Jonathan Macdonalg d o d, A : La Fo Er à T. ec NS ; aT 
į RS a ai aia a aaa engeren EEE ENTE sneeseenont LR Cad RES ene 
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Office of the Commissariat 
. Privacy Commissioner à la protection de 
of Canada la vie privée du Canada 


Privacy Act Breach Report 


For Use by Government of Canada Institutions 


Reporting Breaches Under the Privacy Act 


Federal institutions subject to the Privacy Act are required to notify the Office of the Privacy Commissioner of 
Canada (OPC) and the Treasury Board of Canada Secretariat of all material privacy breaches and of the 
mitigation measures being implemented, if the breach involves sensitive personal information and could 
reasonably be expected to cause serious injury to the individual. 


This reporting form outlines the information that should be provided to the OPC. Report the breach promptly 
rather than waiting to compile all the information requested in the form. Please note that the completed report 
is intended to provide detailed information about the breach itself but must not include personal 
information or protected/classified information. 


The breach report will help determine the type of intervention required by the OPC, such as an informal 
discussion or an investigation. 


Federal institutions should also refer to the Treasury Board's Guidelines for Privacy Breaches. They may also 


Date of the breach: The personnel security screening file was noticed missing on June 20, 2018. 


Date the breach is reported to the September, 2018 
Office of the Privacy Commissioner: 
Name of the institution: Fisheries and Oceans Canada 


ATIP Office contact for the institution Jonathan Macdonald , A/Director, Access to Information and Privacy 
(name, title, telephone number, address, 200 Kent Street, 4th Floor, Ottawa, Ontario KIA 0E6 
email): 613-996-8937, jonathan.macdonald@dfo-mpo.gc.ca 


Contact within department other than Darren Costain, Deputy Director, Security Operations 
the ATIP Office (i.e.: Departmental 200 Kent Street, 4th floor, Ottawa, Ontario K1A 0E6 
Security, Internal Investigations), if 613-990-1575, darren.costain@dfo-mpo.gc.ca 
applicable (name, title, telephone 
number, address, email): 


Coordinates of other contacts, if Melanie Davis, Deputy Director, Privacy and Policy Divison | 
applicable (name, telephone number, 200 Kent Street, 4th floor, Ottawa, Ontario KIA OE6 
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address, email): 4 3-990-3499, ee | 


Description ofthe breach (e.g. cause, any technological issues involved, location, geographical area affected, and 
discovery): 
DFO requested a paper copy of the affected individual's personnel security screening file from Transport Canada, 
located in the NCR on October 6, 2016. DFO realized the file was not needed - the person was not being permanently 
deployed to DFO. Although DFO canceled the request for the affected individual's file, Transport Canada had already 
transferred the file to DFO on October 26, 2016 and DFO received the file on (or around) November 2, 2016. DFO 
believes, the file was immediately returned to Transport Canada but has no record of it being returned as the transmittal 
slips from that period of time were destroyed. Transport Canada has no record of receiving the file after the date it was 
sent to DFO on October 26, 2016. The file was discovered to be missing on June 20, 2018 when the affected individual 
| accepted a position with another government department and his security screening file was requested from DFO. On 
| July 3, 2018, Transport Canada verified with CSIS that DFO held the individual's security clearance. 


; Description of the type of personal information involved (e.g. name, contact information, financial, medical, Social 
insurance Number, Personal Information Bank number): IMPORTANT: Do not include the personal information in 
| question. 

The personnel security screening file contained: biographical information, contact information, financial information, 
‘criminal checks, educational information, date of birth, citizenship status, credit history, employee personnel information, | 

credit history, driver's licence number, place of birth, signature, gender, name, and photographs of individual. 


If the breach involved the loss or theft of computer, tablet or USB key, was it password-protected or encrypted 
and, if so, what is the procedure for implementing such protection? 
n/a 


How many individuals are affected? 


One individual is affected. 


What is the status of individuals affected? (e.g. employees, contractors, public, clients) 


The status of the individual affected is an employee. 


ne 


Do the parties know each other? (e.g. co-workers, ex-spouses) 


n/a - (Only 1 individual was affected.) 


En 


Does the breach involve paper or electronic records? 


| The breach involves paper records, 


| | How broadiy has the personal information been disclosed? 


| There is no indication to suggest that the information was found outside government. 
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ana, 


Has any other organization (e.g. law enforcement) been notified of the breach? If so, when was this organization | 
notified? 
| n/a 


is there any other investigation related to the breach? (e.g. security, criminal) 


No 


Describe the measures taken to contain the breach: 


The employee was advised immediately that their documents were lost. A new credit check was completed and 
provided to the employee to ensure no identity theft had occurred. A thorough search of files at both DFO and Transport 
Canada was completed. Neither department was able to locate the missing documents. 


Has the information been recovered? If not, explain what steps are being taken: 


No, the information has not been recovered despite the thorough search. 


Have the affected individuals been notified of the breach and of their right to complain to the Office of the 
Privacy Commissioner, or will they be notified? (e.g. by letter, telephone) 
Yes, the affected individual was notified by DFO Security. 


Describe the measures contemplated or being taken to prevent a recurrence (e.g. training, new policies or 


procedures): 
The following measures are being contemplated: 


* privacy training for the employees responsible for the breach; | 
* examining existing business processes that track incoming and outgoing files; and | 
+ reviewing retention standards and transmittal slip procedures. | 
f 
| 


Please submit this form to the Office of the Privacy Commissioner of Canada and the 


Treasury Board of Canada Secretariat through one of the following means: 


| By postal mail or by hand: 


Notification Officer Privacy Policy Unit 
Privacy Act investigations Branch | Information and Privacy Policy Division 
Office of the Privacy Commissioner of Canada Chief information Officer Branch 
30 Victoria Street, 15 Floor Treasury Board of Canada Secretariat 


| Gatineau, QC KIA 1H3 90 Elgin Street, 4 Floor 
| Ottawa, ON K1A ORS5 


By email: 
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- Should you require additional information, please call the Notification Officer at 819-994-5444 or 
.1-800-282-1376 (toll-free). 
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From: Notif cation 


To: is, Melanie 

Ce: Macdonald, Jonathan: Rolger Chariotte 

Subject: DFO Privacy Act Breach Report PB-2018-00394 / CB 
Date: Friday, September 7, 2018 5:06:01 PM 
Attachments: imiase0O ton 


We acknowledge receipt of your institution’s incident report to the Office of the Privacy 
Commissioner (OPC) of a Privacy Act breach. 


Our Office will contact you again as soon as we have had the opportunity to review the report. 


In the meantime, please provide any additional information related to this incident as soon as it 


becomes available, and quote OPC file PA-053776. 


Thank you. 


Agent à la notification, Conformité à la Loi sur la protection des renseignements personnels 
en à la protection de la vie privée du Canada 
fboriv.oc.ca / Tél. : 819-994-5444 (direct), 1-800-282-1376 (sans frais) 


Notification Officer, Privacy Act Compliance 
om ice ae the ya Commissioner of Canada 
tificai riv.oc.ca / Tel, : 819-994-5444 (direct), 1-800-282-1376 (toll free) 


From: Davis, Melanie {mailto: Melanie Davis@dfo-mpo.gc.ca] 
Sent: September 7, 2018 07:25 

To: Notification; ‘sec@tbs-sct.gc.ca’ 

Ce: Macdonald, Jonathan; Bolger, Charlotte 

Subject: Material Privacy Breach DFO - PB-2018-00394 / CB 


Good morning, 
This email is to notify your offices of a material privacy breach at Fisheries and Oceans 
Canada as required under TBS’ Guidelines for Privacy Breaches and DFO’s privacy 


framework. The attached form describes the breach and the action taken to control the breach. 
If you require additional information, please don’t hesitate to contact me. 


Thank you, 
Melanie Davis 


Deputy Director, ATIP Secretariat 
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Fisheries and Oceans Canada / Government of Canada 
anis.davisfädfe-mpo.gs.ca / Tel: 613-990-3499 or (BlackBerry) 


Directrice adjointe, Secrétariat de ’AIPRP 
Pêches et Océans Canada / Gouvernement du Canada 

ielanie. davis@dfo-mpo.ge.ca / Tél: 613-990-3499 ou (BlackBerry) 
If ye you have received this communication by mistake, please notify the sender immediately 
and delete the communication without printing, copying or forwarding it. Thank you. / Si 
vous avez reçu cette communication par erreur, veuillez en aviser l'expéditeur 
immédiatement et la supprimer sans l'imprimer, la copier, ou la faire suivre. Merci. 


Attachment: Privacy Breach Incident Report Form 
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From: a A Melanie 

To: Í a, "sec@ths- set oe ca" 

Ce: fan 3 " Jonathan; Bolger, Charlotte 

Subject: Material Privacy Breach DFO - PB-2018-00394 / CB 


Date: pel on. 7, 2018 7:24:54 AM 
Attachments: each, pct 


ASLEEP AEE ENS ELS DEEN S EM SDS OME RODE 


Good morning, 


This email is to notify your offices of a material privacy breach at Fisheries and Oceans Canada 
as required under TBS’ Guidelines for Privacy Breaches and DFO’s privacy framework. The 
attached form describes the breach and the action taken to control the breach. If you require 
additional information, please don’t hesitate to contact me. 


Thank you, 
Melanie Davis 
Deputy Director, ATIP Secretariat 


nonce ies as ea Canada / Government of Canada 
udfo-mypo.ge.ca / Tel: 613-990-3499 or | (BlackBerry) 


Directrice adjointe, Secrétariat de ’AIPRP 
Pêches et resis meres / Gouvernement du Canada 
ca / Tel: 613-990-3499 ou (BlackBerry) 


if yada have received this communication by mislake, please notify the sender immediately and delete the communication 


without printing, copying or forwarding iL Thank you. À Si vous aves regis cetie communication par erreur, veulliez en aviser 


fexpéedieur immeédiatement et ia suporimer sans fimprimer, la coger, ou da faire suivre, Merci. 


Attachment: Privacy Breach Incident Report Form 
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Privacy Act Breach Report 
For Use by Government of Canada institutions 


Reporting Breaches Under the Privacy Act 


Federal institutions subject to the Privacy Act are required to notify the Office of the Privacy Commissioner of 
Canada (OPC) and the Treasury Board of Canada Secretariat of all material privacy breaches and of the 
mitigation measures being implemented, if the breach involves sensitive personal information and could 
reasonably be expected to cause serious injury to the individual. 


This reporting form outlines the information that should be provided to the OPC. Report the breach promptly 
rather than waiting to compile all the information requested in the form. Please note that the completed report 
is intended to provide detailed information about the breach itself but must not include personal 
information or protected/classified information. 


The breach report will help determine the type of intervention required by the OPC, such as an informal 
discussion or an investigation. 


Federal institutions should also refer to the Treasury Board's Guidelines for Privacy Breaches. They may also 
wish to refer to our office's private sector guide, Key Steps for Organizations in Responding to Privacy 
‘Breaches. 


Date of the breach: The personnel security screening file was noticed missing on June 20, 2018. 


Date the breach is reported to the September, 2018 
Office of the Privacy Commissioner: 


Name of the institution: Fisheries and Oceans Canada | 


ATIP Office contact for the institution Jonathan Macdonald, A/Director, Access to Information and Privacy 
(name, title, telephone number, address 200 Kent Street, 4th Floor, Ottawa, Ontario KIA 0E6 
email): 613-996-8937, jonathan.macdonald@dfo-mpo.gc.ca 


Contact within department other than 
the ATIP Office (i.e. Departmental 
Security, Internal Investigations), if 
applicable (name, title, telephone 
number, address, email): 


Darren Costain, Deputy Director, Security Operations 
200 Kent Street, 4th floor, Ottawa, Ontario KIA 0E6 
613-990-1575, darren.costain@dfo-mpo.gc.ca 


Melanie Davis, Deputy Director, Privacy and Policy Divison 
200 Kent Street, 4th floor, Ottawa, Ontario KIA 0E6 


Coordinates of other contacts, if 
applicable (name, telephone number, 


Page # 


000057 


Office of the Commissariat 
, Privacy Commissioner å la protection de 
of Canada la vie privée du Canada 


613-990-3499, melanie. davis@dfo-mpo.gc.ca | 


Description of the breach (e.g. cause, any technological issues involved, location, geographical area affected, and 

discovery): 

DFO requested a paper copy of the affected individual’s personnel security screening file from Transport Canada, 

located in the NCR on October 6, 2016. DFO realized the file was not needed - the person was not being permanently 

deployed to DFO. Although DFO canceled the request for the affected individual's file, Transport Canada had already 
transferred the file to DFO on October 26, 2016 and DFO received the file on (or around) November 2, 2016. DFO | 
; believes, the file was immediately returned to Transport Canada but has no record of it being returned as the transmittal 
slips from that period of time were destroyed. Transport Canada has no record of receiving the file after the date it was 
sent to DFO on October 26, 2016. The file was discovered to be missing on June 20, 2018 when the affected individual 
accepted a position with another government department and his security screening file was requested from DFO. On 
July 3, 2018, Transport Canada verified with CSIS that DFO held the individuals security clearance. 


Description of the type of personal information involved (e.g. name, contact information, financial, medical, Social 
Insurance Number, Personal Information Bank number): IMPORTANT: Do not include the personal information in 
question. 

The personnel security screening file contained: biographical information, contact information, financial information, 
criminal checks, educational information, date of birth, citizenship status, credit history, employee personnel information, 
credit history, driver's licence number, place of birth, signature, gender, name, and photographs of individual. 


address, email): 


If the breach involved the loss or theft of computer, tablet or USB key, was it password-protected or encrypted 
and, if so, what is the procedure for implementing such protection? 
n/a 


i 


How many individuals are affected? 


One individual is affected. 


What is the status of individuals affected? (e.g. employees, contractors, public, clients) 


The status of the individual affected is an employee. 


Do the parties know each other? (e.g. co-workers, ex-spouses) 


| n/a - (Only 1 individual was affected.) 


Ce AAA e: 


| 
x x 
| Does the breach involve paper or electronic records? 


| The breach involves paper records. 


ee 


How broadly has the personal information been disclosed? | 


There is no indication to suggest that the information was found outside government. 
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Has any other organization (e.g. law enforcement) been notified of the breach? If so, when was this organization 
notified? 
n/a 


Is there any other investigation related to the breach? (e.g. security, criminal) 


No 


The employee was advised immediately that their documents were lost. A new credit check was completed and 
provided to the employee to ensure no identity theft had occurred. A thorough search of files at both DFO and Transport 
Canada was completed. Neither department was able to locate the missing documents. 


| Has the information been recovered? If not, explain what steps are being taken: 


| 
| No, the information has not been recovered despite the thorough search. 


Have the affected individuals been notified of the breach and of their right to complain to the Office of the 
Privacy Commissioner, or will they be notified? (e.g. by letter, telephone) 
Yes, the affected individual was notified by DFO Security. 


| Describe the measures contemplated or being taken to prevent a recurrence (e.g. training, new policies or 


procedures): 
The following measures are being contemplated: 


* privacy training for the employees responsible for the breach; 
* examining existing business processes that track incoming and outgoing files; and 
* reviewing retention standards and transmittal slip procedures. 


Please submit this form to the Office of the Privacy Commissioner of Canada and the 
Treasury Board of Canada Secretariat through one of the following means: 


| By postal mail or by hand: 


Notification Officer Privacy Policy Unit 

Privacy Act Investigations Branch Information and Privacy Policy Division 
Office of the Privacy Commissioner of Canada Chief Information Officer Branch 

30 Victoria Street, 15t Floor Treasury Board of Canada Secretariat 
Gatineau, QC KIA 1H3 90 Elgin Street, 4% Floor 


Ottawa, ON KTA OR5 


By email: 
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notification@oriv.cc.ca sec@tbs-sct.ge.ca 


| Should you require additional information, please call the Notification Officer at 819-994-5444 or 
| 1-800-282-1376 (toll-free). 
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Request Summary Report 
PB-2018-00394 / CB - Fisheries and Oceans 


Category: Routine Date on Request: 2018-07-11 
Received: . 2018-07-11 Date Initially Received: 2018-07-11 
Due: 2018-07-25 l Requester File Ref. #: 

Closed: 2018-09-18 Jacket Number: 

Officer Assigned: Bolger, Charlotte Request Transferred In: No 
Decision Maker: Days Taken: 69 

Days Allowed: 14 

Summary: Date of incident: Around November 2, 2016 


Affected individuals: 1 
Summary: Improper or unauthorized disciosure of personal information 


Full Text: { ] Personnel Security Screening File went missing when transferred between departments. DFO believes that 
the file was received by Transport Canada but no longer has the transmittal slip to prove it. Transport Canada 
has not been able to find the file. The file was transferred in 2016, but it was only discovered to be missing in 
2018 when DFO Security received a request to verify his clearance for another department. 


ACTIVITY 
Action Contact Created Due Completed On Hold Elapsed 
§- RESPONSE-PB Requester 2018-09-04 2018-09-04 No 6 
Comments: 
3. Material PB - Notify OPC and Access to Information and Privacy- 2018-08-30 2018-09-10 2018-09-06 No 4 
TBS BOLGER, Charlotte 
Comments: Melanie emailed Security a copy of our report to confirm that he agreed with the findings. He 
indicated that he did (see attached). 
BOLGER, Charlotte 
Comments: Response from Transport Canada, confirming they do not have the file and suggesting that 
they did not receive it 
2b - Material - YES Fill out the Access to Information and Privacy - 2018-08-28 2018-08-28 No 0 
Template BOLGER, Charlotte 
Comments: 
1b - Breach - YES Access to Information and Privacy- 2018-08-28 2018-08-28 No 0 
BOLGER, Charlotte 
Comments: 
Email OO Access to Information and Privacy - 2018-07-48 —™*” 2018-08-18 No 31 
BOLGER, Charlotte 
Comments: 
Email Access to Information and Privacy - 2018-07-17 2018-07-17 No Q 
BOLGER, Charlotte 
Comments: Email Darren for clarification on what sensitive information was in the security file. 
4 - Privacy Breach Report Access to information and Privacy - 2018-07-11 2018-07-11 No 0 
BOLGER, Charlotte 
Comments: 
Telephone Access to Information and Privacy - 2018-07-11 2018-07-11 No 0 
BOLGER, Charlotte 
Conunents: Sarah spoke to Darren Costain in DFO Security. He clarified that it is unknown whether the file 
was lost by DFO or by Transport Canada. Sarah summarized this in an email to me, which is 
included in the original request. 
12/21/2018 10:37:29 AM / Charlotte Bolger Page 172 
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Request Summary Report 
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Original Request Access to information and Privacy - 2018-07-11 2018-07-11 No 0 
BOLGER, Charlotte 


Comments: 

CLOSING 
Date Closed: 2018-09-18 Method of Access: Not Applicable 
Date Communicated: 2018-09-04 Method of Delivery: Email 
Request Disposition: PPD/AORs -Treated informally Translation: 
Pages Received: 0 Request Transferred Out: No 
Pages Reviewed: 0 
Pages Released: 0 
Pages Not Relevant: 0 
Comment: 
Disposition: Release Date: 
Pages Reviewed: Method of Delivery: 
Pages Released: Translation: 
Pages Not Relevant: Method of Access: 
Version : 

Sections: 


AccessPro Case Management: 
AccessPro Redaction: 
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